Vulnerabilities > Google > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-09-27 CVE-2019-9399 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Google Android 10.0
The Print Service is susceptible to man in the middle attacks due to improperly used crypto.
network
high complexity
google CWE-327
5.9
2019-09-27 CVE-2019-9391 Use of Uninitialized Resource vulnerability in Google Android 10.0
In libxaac, there is a possible out of bounds read due to uninitialized data.
network
low complexity
google CWE-908
6.5
2019-09-27 CVE-2019-9385 Out-of-bounds Read vulnerability in Google Android 10.0
In libxaac, there is a possible out of bounds read due to a missing bounds check.
network
low complexity
google CWE-125
6.5
2019-09-27 CVE-2019-9384 Unspecified vulnerability in Google Android 10.0
In LockPatternUtils, there is a possible escalation of privilege due to an improper permissions check.
local
low complexity
google
6.7
2019-09-27 CVE-2019-9383 Out-of-bounds Read vulnerability in Google Android 10.0
In NFC server, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-125
5.0
2019-09-27 CVE-2019-9380 Missing Authorization vulnerability in Google Android 10.0
In the settings UI, there is a possible spoofing vulnerability due to a missing permission check.
network
low complexity
google CWE-862
6.5
2019-09-27 CVE-2019-9379 Improper Input Validation vulnerability in Google Android 10.0
In libstagefright, there is a possible resource exhaustion due to a missing bounds check.
network
low complexity
google CWE-20
6.5
2019-09-27 CVE-2019-9376 Excessive Iteration vulnerability in Google Android 8.0/8.1/9.0
In Account of Account.java, there is a possible boot loop due to improper input validation.
local
low complexity
google CWE-834
5.5
2019-09-27 CVE-2019-9375 Out-of-bounds Write vulnerability in Google Android 10.0
In hostapd, there is a possible out of bounds write due to a race condition.
local
high complexity
google CWE-787
6.4
2019-09-27 CVE-2019-9373 Deserialization of Untrusted Data vulnerability in Google Android 10.0
In JobStore, there is a mismatched serialization/deserialization for the "battery-not-low" job attribute.
local
low complexity
google CWE-502
5.5